ZimReaper is a browser-resident JavaScript espionage payload used by the Russia-aligned threat actor TA488, also tracked as Laundry Bear and Void Blizzard, in campaigns against Zimbra Collaboration Suite webmail servers. It was deployed through exploitation of CVE-2025-66376, a stored cross-site scripting flaw in Zimbra Classic UI, in so-called half-click attacks where a victim only needed to open or preview a crafted email for code to execute inside an authenticated webmail session.
Once executed, ZimReaper harvests mailbox and account-access data from the victim’s Zimbra session. Reported capabilities include theft of CSRF tokens, browser-autofilled or browser-saved passwords, two-factor authentication scratch or recovery codes, Zimbra version and configuration details, and enumeration of the organization’s Global Address List. It also exports and exfiltrates up to roughly 90 days of mailbox contents. Exfiltration has been observed over both HTTP POST and DNS-based channels.
ZimReaper also establishes durable access by creating an app-specific password, commonly labeled to resemble legitimate Zimbra usage, enabling continued IMAP, POP3, or SMTP access without normal two-factor authentication prompts. This persistence can survive ordinary password changes unless the unauthorized application password is explicitly removed. The malware has been associated with espionage targeting of Ukrainian government entities, U.S. government and defense-related organizations including nuclear and defense-industrial targets, and additional government, education, transportation, financial, scientific, and other organizations across Europe, NATO countries, the CIS, Africa, and the United States.
ZimReaper is notable as the predecessor to OWAReaper, with later tooling retaining substantial behavioral and code overlap. Its use reflects a focused tradecraft pattern of abusing webmail rendering flaws to gain access, steal credentials and communications, and maintain covert mailbox access for intelligence collection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Proofpoint linked OWAReaper to TA488 based on behavioral similarities with ZimReaper, malware previously used by the group against Zimbra email servers. In that campaign, TA488 exploited another XSS flaw, CVE-2025-66376, to steal emails, passwords, application passcodes and two-factor authentication codes. | Proofpoint linked OWAReaper to TA488 based on behavioral similarities with ZimReaper, malware previously used by the group against Zimbra email servers.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Proofpoint linked OWAReaper to TA488 based on behavioral similarities with ZimReaper, malware previously used by the group against Zimbra email servers.
...ultimately resulting in the deployment of a JavaScript payload dubbed ZimReaper that's capable of harvesting 90 days of the victim's mail and other valuable data.
...ultimately resulting in the deployment of a JavaScript payload dubbed ZimReaper that's capable of harvesting 90 days of the victim's mail and other valuable data.
Once the JavaScript payload, dubbed ZimReaper by Proofpoint, executes, it performs the following malicious actions: steals the CSRF token and the browser's autofilled password, retrieves 2FA scratch codes, creates an app-specific password named ZimbraWeb, brute-forces the Global Address List, and exfiltrates 90 days of the victim's mail.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
La technique dite half-click exploit ne nécessite que l’ouverture ou la prévisualisation de l’email pour déclencher l’exécution du code malveillant, sans aucune interaction supplémentaire.
Russia-affiliated cyber espionage group Laundry Bear (aka Void Blizzard, aka TA488) is exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange... The loader ultimately delivers OWAReaper, a backdoor that is executed in the reading pane of Outlook Web Access (OWA)
Création d’un mot de passe applicatif nommé “ZimbraWeb” pour un accès persistant via IMAP/POP3/SMTP sans 2FA
MITRE ATT&CK Mapping Tactic Technique ID Technique Name Credential Access T1003 OS Credential Dumping (Browser Passwords)
Impact: Full account takeover — attackers steal session tokens, 2FA codes, browser-saved passwords, the entire Global Address List, and up to 90 days of mailbox data.
It then creates two invisible input elements in the DOM and waits for the browser's autofill to enter the username and password to gather the user’s OWA saved credentials.
MITRE ATT&CK Mapping Tactic Technique ID Technique Name Collection T1114 Email Collection
Exfiltration des 90 derniers jours d’emails via HTTP POST (format TGZ)
Ping du serveur C2 pour confirmer l’exploitation ... Exfiltration via requêtes DNS ... Exfiltration des 90 derniers jours d’emails via HTTP POST
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously used by TA488 against Zimbra email servers to steal emails, passwords, application passcodes and two-factor authentication codes.
Payload JavaScript used after exploitation of Zimbra webmail that steals session and credential material, collects 2FA codes, enumerates address data, exfiltrates recent emails, and establishes persistent access by creating an application password that bypasses 2FA for mail protocols.
Earlier related payload used by the same threat actor in a 2025 campaign against Zimbra mailservers; described as the predecessor/evolutionary basis for OWAReaper and sharing code, behavior, and similar error-handling and reporting mechanisms.
A JavaScript payload used in prior Zimbra exploitation that harvests 90 days of victim email and other valuable data; described as the predecessor/evolutionary basis for OWAReaper.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.